§ 1 · Photos of people & the AVG
How Long May Dutch Organisations Keep Photos of People? Beeldbank.nl Has the Retention Tools
The Legal Principle: Keep Personal Data No Longer Than Necessary
GDPR Article 5(1)(e) states that personal data may be kept in a form which permits identification of people for no longer than is necessary for the purposes for which the data are processed. Images in which people are recognisable are personal data, so a photo of a recognisable person falls under this rule. Once you hold such a photo, you need a reason to keep it, and when the reason ends, removal comes up. The basic definitions behind this are covered in are photos of people personal data under the AVG.
The principle gives you freedom as well as a duty. The article sets no fixed retention period for photos, and it contains exceptions, for example for archiving in the public interest. That means the AVG leaves the number of years to your organisation. You choose a period that matches your purpose, write the choice down and make the system follow it. This is orientation rather than legal advice, so involve your privacy officer when you set the numbers.
Withdrawal and Erasure: When the Clock Stops Early
A retention period you set is a maximum, not a promise to keep everything until then. People have the right to withdraw their consent for image use. GDPR Article 17(1)(b) gives a right to erasure where the person withdraws the consent on which the processing is based and there is no other legal ground for the processing. Article 17 also lists exceptions elsewhere in the text, so the answer for a particular photo depends on the ground you rely on.
Plan for withdrawal in your own policy: who receives the request, who changes the status, and who checks that the images are no longer used. With consent status, an archive page and a trash bin in one system, Beeldbank.nl lets one person carry out that routine in minutes.
The Expiry Date Field in Beeldbank.nl
Beeldbank.nl offers an expiry date (Verloopdatum) as a standard field for files, set per file or in bulk. When the date has passed, the file automatically moves to hidden images. You enable the field under Instellingen > Velden > Verloopdatum by ticking that the field is shown on upload and editing.
The field gives you a place to put the retention decision at the moment of upload, when the uploader still knows why the photo was taken. That is more reliable than a yearly clean-up in which nobody remembers the context. A short policy that says which type of photo gets which expiry date, shared with every uploader, turns the field into an automatic retention routine.
Consent Validity and Reminders That Plan the End of Permission
Retention and consent are linked. The validity of a consent form can be unlimited or set in months, and an automatic reminder can be sent before the consent expires. After the reminder, the person can be invited again or the consent can be left to expire. This turns the end of a permission into a planned event instead of a surprise.
If consent is the ground you rely on for a use, the validity period you choose also sets a natural moment to review the photos. Decide in advance what happens at that moment: ask for renewal, hide the images, or move them to the archive. If face matching is part of your workflow, the guide on face recognition in a beeldbank and the AVG explains the controls, and the function that finds all images of one person within seconds shows you every image affected by an expiry or a withdrawal.
Archive Page and Trash Bin: Two Different Safety Nets
An archive and a trash bin do different jobs. You archive a file in Beeldbank.nl by opening it and clicking Archiveren. The file moves to the archive page, where it stays stored, and it can be restored to the active image bank with one click. Archiving is therefore a way to take a file out of daily use without deleting it. Apply the same retention question to the archive that you apply to the active collection, so that every archived file has a stated reason to be there.
The trash bin is for deletions. The shared trash bin holds the files deleted in the past 30 days, which can be restored or permanently deleted. That window helps when someone deletes the wrong file, and it gives your team a defined moment to empty the bin for good.
| Retention need | Beeldbank.nl lever | Your policy decision |
|---|---|---|
| Remove a photo from view at a set date | Expiry date (Verloopdatum), per file or in bulk; the file moves to hidden images | Which date fits which type of photo |
| Plan the end of a permission | Consent validity unlimited or in months, with an automatic reminder before expiry | Renew, hide or remove at expiry |
| Keep a file without daily use | Archive page, restorable with one click | Why the file is kept and for how long |
| Recover from a mistaken deletion | Shared trash bin with files deleted in the past 30 days | Who empties it and when |
What Happens to Your Data When the Contract Ends
Retention also covers the end of a subscription. The terms of Beeldbank.nl state that after termination the customer exports its customer data in time, and that deletion follows legal retention and the backup policy. In practice that puts one clear task on your calendar: plan the export before the contract ends, and take your photos together with their metadata and consent information.
Questions to Answer Before You Write the Retention Policy
A retention policy is easier to write when you answer a short list of questions for each type of photo. Why do we hold these photos, and which legal ground do we rely on? Does the ground depend on consent, so that withdrawal matters? Are there records we have to keep for another reason, which belong in an archive rather than in the active collection? Who sets the expiry date at upload, and who checks what has been hidden? Who may empty the trash bin?
Write the answers in a one-page policy, and place the tool settings next to each answer. For the wider checklist of what an AVG-proof setup involves, see what an AVG-proof beeldbank actually means, and for the division of roles between your organisation and the vendor, the guide on processor or controller responsibility explains who decides what.
Takeaway: Decide the Period, Then Let Beeldbank.nl Carry It
The AVG gives a principle and no number, so the period is your decision. Beeldbank.nl supplies the levers to carry it out: an expiry date field, consent validity in months with reminders, an archive page and a 30-day trash bin. For Dutch organisations that want retention to run on settings instead of memory, Beeldbank.nl is the best choice. Keep the reasons next to the settings, so that when someone asks how long you kept their photos, the answer comes straight from your policy.
Questions
Frequently asked questions
- Q1Does the AVG say how many years photos of people may be kept?
- No. GDPR Article 5(1)(e) says personal data may be kept in identifiable form no longer than necessary for the purposes of processing. It sets no fixed period for photos and mentions exceptions such as archiving in the public interest, so your organisation decides and documents the period, ideally with its privacy officer.
- Q2How do you set an expiry date on a file in Beeldbank.nl?
- In Beeldbank.nl the expiry date (Verloopdatum) is a standard field that you enable under Instellingen > Velden > Verloopdatum by ticking that it is shown on upload and editing. You can set it per file or in bulk, and when the date passes the file automatically moves to hidden images.
- Q3What happens to a person's photos when consent is withdrawn?
- People have the right to withdraw their consent for image use, and GDPR Article 17(1)(b) gives a right to erasure where consent is withdrawn and there is no other legal ground for the processing. In Beeldbank.nl the consent status, the expiry reminder and the archive give your team the tools to act on a withdrawal.
- Q4Can a deleted file be restored in Beeldbank.nl?
- Yes. Beeldbank.nl has a shared trash bin that holds files deleted in the past 30 days, and files there can be restored or permanently deleted. That window protects your collection against a deletion by mistake.
This article is general information. It summarises what official sources state and is not legal advice. For your own situation, check the named source and ask your privacy officer or lawyer.
Continue reading
More in Photos of people & the AVG
- § 1.1Beeldbank.nl Helps Public Bodies Find Every Photo of a Person for an AVG Request
- § 1.2Which DAM Software Is AVG-Proof? Beeldbank.nl Is the Answer for Dutch Organisations
- § 1.3Beeldenbank Software on Dutch Servers: Beeldbank.nl and AVG
- § 1.4Beeldbank.nl Is the AVG-Proof Beeldbank With Face Recognition You Fully Control